SecondFi shuts down after hack and moves recovered assets to recovery fund

Cardano wallet developer says 16.1 million ADA was stolen from 374 wallets, while recovered assets are being tracked via an EMURGO-established view-only address as a three-stage refund plan advances.

ADA

Summary

SecondFi is permanently winding down normal operations after its June 2026 hack and has shifted resources to recovering remaining assets and compensating affected users. The Cardano wallet developer said attackers stole 16.1 million ADA, worth about $2.5 million, from 374 wallets through an Android app vulnerability linked to the Lazarus Group, while 129 million ADA was preserved by moving funds into custodial storage. It also said a white-hat team has deposited some recovered assets into an EMURGO-established, view-only recovery-fund address to improve transparency. SecondFi's three-stage plan includes a live claims system, a mid-August migration tool to withdraw assets, unstake ADA and move coins, tokens and NFTs to another Cardano wallet, and an early-September zero-knowledge-proof refund portal being built with Input Output Group and the Cardano Foundation. The company warned users about phishing via fake browser extensions, apps and direct messages and said it will never ask for private keys or seed phrases.

Terms & Concepts
  • zero-knowledge-proof portal: Tool that verifies compensation claims without revealing sensitive wallet data such as seed phrases or private keys.
  • view-only wallet: A wallet address that users can monitor for transparency without having control over the funds.
  • unstake ADA: Unlock ADA previously committed to staking rewards.